A new campaign, known as Zoom Stealer, is affecting 2.2 million Chrome, Firefox, and Microsoft Edge users through 18 extensions that collect data related to online meetings, such as URLs, IDs, topics, descriptions, and embedded passwords. Zoom Stealer is one of three browser extension campaigns that have reached over 7.8 million users over seven years and are attributed to a single threat actor known as DarkSpectre.
See also: Zoom Security Update – Fixing Multiple Vulnerabilities

This actor is believed to be linked to China and is also responsible for the previously reported GhostPoster, which targeted Firefox users, and ShadyPanda, which delivered spyware payloads to Chrome and Edge users. ShadyPanda remains active via nine extensions and an additional 85 'sleepers' that build a user base before becoming malicious via updates, according to researchers at supply chain security firm Koi Security.
Attribution to a China-linked threat actor is now clearer based on hosting servers on Alibaba Cloud, ICP records, code artifacts containing Chinese language strings and comments, activity patterns matching the China time zone, and profitability targeting tailored to Chinese e-commerce. Not all of the 18 extensions in the Zoom Stealer campaign are related to meetings.
Some can be used to download videos or act as recording assistants, such as Chrome Audio Capture and Twitter X Video Downloader, which are still available in the Chrome Web Store. Koi Security researchers note that all extensions in the Zoom Stealer campaign request access to 28 video conferencing platforms (e.g. Zoom, Microsoft Teams, Google Meet, and Cisco WebEx) and collect the following data:
See also: BlueNoroff distributes MacOS malware via deepfake videos in Zoom meetings

– Meeting URLs and IDs, including embedded passwords
– Registration status, topics and scheduled times
– Speaker and host names, titles, biographies and profile photos
– Company logos, graphics and session metadata
This data is extracted via WebSocket connections and transmitted to threat actors in real time, triggered when victims visit webinar registration pages, join meetings, or navigate conferencing platforms.
Koi Security says this data can be used for corporate espionage and information sales, potentially facilitating social engineering attacks or even selling meeting links to competitors. By systematically collecting meeting links, attendee lists, and corporate information from 2.2 million users, DarkSpectre has created a database that could enable large-scale impersonation operations, providing attackers with credentials to join confidential calls, attendee lists to know who to impersonate, and the framework to make those impersonations convincing.
See also: Vladimir Putin "took issue" with Microsoft and Zoom

Users should carefully review the permissions requested by these extensions and limit their number to the bare minimum. Koi Security has reported the offending extensions, but many remain in the Chrome Web Store. Researchers have published a full list of active DarkSpectre extensions.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
